The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2013-4706: Undefined Security Weakness6.5 MediumN/A1%Sep 20, 2013
CVE-2013-4259: Undefined Security Weakness3.3 LowN/A0%Sep 16, 2013
CVE-2013-4959: Exposure of Sensitive Information to an Unauthorized Actor3.3 LowN/A0%Aug 20, 2013
CVE-2013-4206: Improper Restriction of Operations within the Bounds of a Memory Buffer6.3 MediumN/A2%Aug 19, 2013
CVE-2013-4852: Undefined Security Weakness7.3 HighN/A3%Aug 19, 2013
CVE-2013-4207: Improper Restriction of Operations within the Bounds of a Memory Buffer5.3 MediumN/A2%Aug 19, 2013
CVE-2012-3039: Undefined Security Weakness8.1 HighN/A1%Aug 9, 2013
CVE-2013-4652: Undefined Security Weakness9.8 CriticalN/A6%Jul 31, 2013
CVE-2013-0137: Undefined Security Weakness9.8 CriticalN/A13%Jun 29, 2013
CVE-2013-2342: Undefined Security WeaknessN/AN/A1%Jun 29, 2013
CVE-2013-1246: Undefined Security WeaknessN/AN/A2%May 31, 2013
CVE-2013-1193: Undefined Security WeaknessN/AN/A2%Apr 16, 2013
CVE-2013-2302: Exposure of Sensitive Information to an Unauthorized ActorN/AN/A0%Apr 4, 2013
CVE-2013-0714: Improper Input Validation9.8 CriticalN/A6%Mar 20, 2013
CVE-2013-0713: Improper Input ValidationN/AN/A2%Mar 20, 2013
CVE-2013-0712: Improper Input ValidationN/AN/A3%Mar 20, 2013
CVE-2013-0711: Improper Input Validation7.5 HighN/A3%Mar 20, 2013
CVE-2013-1423: Improper Link Resolution Before File Access7.8 HighN/A0%Mar 12, 2013
CVE-2012-4702: Undefined Security WeaknessN/AN/A4%Mar 11, 2013
CVE-2010-5107: Uncontrolled Resource Consumption7.5 HighN/A17%Mar 7, 2013
CVE-2013-1154: Undefined Security Weakness5.3 MediumN/A2%Mar 7, 2013
CVE-2013-0220: Improper Restriction of Operations within the Bounds of a Memory Buffer7.5 HighN/A3%Feb 24, 2013
CVE-2012-5536: Improper Input Validation7.0 HighN/A0%Feb 22, 2013
CVE-2012-4694: Undefined Security Weakness8.1 HighN/A1%Feb 15, 2013
CVE-2013-0176: Undefined Security Weakness7.5 HighN/A3%Feb 5, 2013
1651-1675 of 1974